|
Item |
Details |
|
|---|---|---|
|
Prior Confirmation |
|
|
|
Name ID |
〇 |
Email address |
|
Custom attribute Note: For how to configure custom attributes, see here |
||
|
SP-side Configuration |
〇 |
Configured by the administrator |
|
Request configuration from the SP |
||
|
Provisioning |
API-based Provisioning supported (account management available in TrustLogin) |
|
| 〇 |
SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported) |
|
|
|
None (accounts created in each system) |
|
|
Access Method |
〇 |
SP-Initiated SSO |
|
〇 |
IdP-Initiated SSO |
|
|
Verified Operation by Device |
〇 |
PC - Browser |
|
ー |
PC - Desktop App |
|
|
〇 |
iOS - Standard Browser (Safari) |
|
|
〇 |
iOS - TrustLogin Mobile App In-App Browser (*) |
|
|
〇 |
iOS - Native App |
|
|
〇 |
Android - Standard Browser (Chrome) |
|
|
〇 |
Android - TrustLogin Mobile App In-App Browser (*) |
|
|
〇 |
Android - Native App |
|
(*) Login itself is possible via the in-app browser of the TrustLogin mobile app; however, since the in-app browser is not supported by Datadog, it may not function correctly.
Preparation
Datadog's SAML JIT supports the following two patterns.
- Sync the TrustLogin user's "Last Name," "First Name," and "Email Address" to manage Datadog user information (user role management is handled in Datadog)
- Sync the TrustLogin user's "Last Name," "First Name," "Email Address," and "Group" to manage Datadog user information and role mapping
If you are not using option 2, "Mapping to Datadog Roles," this preparation step is not required.
Please proceed to the next section, "TrustLogin Admin Page Settings."
Create a Group and Assign Members
Create a group to map to a Datadog role group, and assign members to it.
(You may use an existing group instead, if it suits your operations.)
For instructions on how to create a group and assign members, please refer to the following page.
Register a Group
[Configuration Example]
- Create an "Administrator" group and assign it to Datadog's "Datadog Admin Role" role
- Create a "General User" group and assign it to Datadog's "Datadog Standard Role" role
With this configuration, a user belonging to the "Administrator" group will automatically be assigned the "Datadog Admin Role" role when logging in to Datadog via SAML. Users who do not belong to any of the configured groups will not be able to log in to Datadog.
TrustLogin Admin Page Settings
-
Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register SAML App" button at the top right of the screen.
- Register the "Application Name" and "Icon" (optional).
- Download the metadata from the "Download Metadata" button under "Identity Provider Information."
Now, switch to configuring Datadog.
Do not click the "Register" button yet — open Datadog in a separate window.
Datadog Settings
Basic SAML Settings
- Log in to Datadog, open "Organization Settings" from the icon in the bottom left, and click the "Configure" button under "Login Methods > SAML."
- Use the "Choose File" button to select the metadata you downloaded from TrustLogin, then click the "Upload and Enable" button.
- Open the SAML settings screen again and check "Identity Provider (IdP) Initiated Login."
Make a note of the "Single Sign-on URL," "Service Provider Entity ID," and the two "Assertion Consumer Service URL"
values.
- Specify the domain(s) allowed to create new users via SAML JIT, and add them using "Add Domain."
- Specify the user role that is assigned by default when a new user is created via SAML JIT. (This does not update the roles of existing users, and does not apply if you are mapping to Datadog roles.)
Save your settings by clicking the "Save Changes" button.
Configuring Mapping to Datadog Roles
If you are not mapping to Datadog roles, this configuration is not required.
Please proceed to the next section, "TrustLogin Admin Page Settings (Continued)."
- Open "Organizarion Settings > SAML Group Mappings" and click "+New Mappping."
- Under ① Add Attribute, enter "groups" and the group name you created during preparation, then under ② Assign Role, select the role to assign.
Add it by clicking "Save & Close."
- Create as many rules as needed for the roles you want to assign, then click "Enable Mappings." A confirmation screen will appear; click "Enable Mappings" again to activate the mapping.
Return to the TrustLogin settings again.
TrustLogin Admin Page Settings (Continued)
- Configure "Service Provider Settings" as follows.
Login URL The "Single Sign-on URL" obtained from Datadog Entity ID The "Service Provider Entity ID" obtained from Datadog Name ID Format "emailAddress" ACS URL to Service Click the "+" on the right to add a row.
Enter the two "Assertion Consumer Service URL" values obtained from Datadog
into the two rows. The order does not matter.
-
Click the "Specify Custom Attribute" button under "SAML Attribute Settings," then add a row (attribute) using the "Add SAML Attribute" button and configure it as follows.
The groups row should only be configured if you are mapping to Datadog roles.
For the group attribute value, select the group name from the dropdown; you can add multiple groups using the "+" mark on the right.
Service Provider Attribute TrustLogin (IdP) Attribute Attribute Name Attribute Type Attribute Name Attribute Value urn:mace:dir:attribute-def:eduPersonPrincipalName
Basic urn:mace:dir:attribute-def:eduPersonPrincipalName
Member Member - Email Address urn:mace:dir:attribute-def:sn Basic urn:mace:dir:attribute-def:sn Member Member - Last Name urn:mace:dir:attribute-def:givenName Basic urn:mace:dir:attribute-def:givenName Member Member - First Name groups Basic groups Group Select the group name you configured and add it using the "+" button
[If you are not mapping to Datadog roles]
[If you are mapping to Datadog roles]
- Save by clicking the "Register" button.
TrustLogin User Settings
① When a User Adds the App via My Page
- Click the "Add App" button on "My Page."
- On the "Register App" screen, select the custom SAML app you created, and click the "Next" button at the top right of the screen.
- If you want to change the "Display Name," enter it, then click the "Register" button.
- Click the app on "My Page" or in the browser extension, and confirm that login succeeds.
②When an Administrator Adds a Member
- Search for and click the custom SAML app you created in the "Admin Page > App" menu.
- Click "Add Member," select the user to add from the member list, and click the "Register" button to add them.
How to Log In via the Datadog Mobile App
- Log in to the TrustLogin mobile app in advance.
- Open the mobile app, select your region, and click the "Sign In" button.
- Click "Using Single Sign-On (SAML)?"
On the next screen, enter your email address and send it by clicking "Send email."
- You will receive an email containing a login URL at your email address; open the "Mobile Login" link on your mobile device. Login will be complete once you click the "Authorize" button in the mobile app.